10-Q: CrowdStrike Holdings Reports Q3 Results, Impacted by July Incident

Sentiment:

Quarterly Report


CrowdStrike Holdings' Q3 results show revenue growth but are impacted by the July 19th incident, leading to increased expenses and a net loss.

Delay expectedThe July 19th incident has resulted in delays in creating sales opportunities and longer sales cycles.
Worse than expectedThe company reported a net loss of $16.8 million, a significant decrease from the net income of $26.7 million in the same period last year, indicating worse than expected results.

Summary

  • CrowdStrike Holdings reported a net loss of $16.8 million for the third quarter of fiscal year 2025, compared to a net income of $26.7 million in the same period last year.
  • The company's total revenue increased by 29% year-over-year to $1.01 billion, with subscription revenue growing by 31% to $962.7 million.
  • Professional services revenue decreased by 10% to $47.4 million.
  • Operating expenses increased by 38% to $810.8 million, driven by higher sales and marketing, research and development, and general and administrative costs.
  • The company's annual recurring revenue (ARR) reached $4.0 billion, a 27% increase year-over-year.
  • The dollar-based net retention rate was 115% as of October 31, 2024.
  • The July 19th incident resulted in significant legal and professional service expenses, totaling $39.1 million for the nine months ended October 31, 2024.
  • The company acquired Flow Security for $96.4 million in cash and $0.5 million in replacement equity awards.

Sentiment

Score: 5

Explanation: The document presents a mixed picture. While revenue growth and ARR are positive, the net loss and the impact of the July 19th incident are significant concerns. The company's future performance will depend on its ability to manage these challenges.

Positives

  • Subscription revenue continues to grow strongly, increasing by 31% year-over-year.
  • Annual recurring revenue (ARR) reached $4.0 billion, demonstrating continued growth in the customer base.
  • The company's dollar-based net retention rate remains strong at 115%, indicating good customer retention and expansion.
  • The company completed the acquisition of Flow Security, expanding its product offerings.

Negatives

  • The company reported a net loss of $16.8 million for the quarter, a significant decrease from the net income of $26.7 million in the same period last year.
  • Operating expenses increased significantly by 38%, impacting profitability.
  • Professional services revenue decreased by 10%, indicating a potential weakness in that segment.
  • The July 19th incident has resulted in significant expenses and is expected to continue to impact future results.

Risks

  • The July 19th incident has had, and is expected to continue to have, an adverse effect on the company's business, sales, customer and partner relations, reputation, results of operations and financial condition.
  • The company faces intense competition in the cybersecurity market, which could lead to loss of market share.
  • The company's solutions may fail to detect or prevent incidents, which could harm its brand and reputation.
  • The company relies on third-party data centers, and any disruption could negatively affect its ability to maintain the performance and reliability of its platform.
  • The company's sales cycles can be long and unpredictable, requiring considerable time and expense.
  • The company is subject to various legal proceedings, including those related to the July 19th incident, which could result in significant costs and liabilities.
  • The company's international operations expose it to significant risks, including currency fluctuations and compliance with foreign laws and regulations.
  • The company's reliance on key personnel and the ability to attract and retain qualified employees is critical to its success.
  • The company's results of operations may fluctuate significantly, making future results difficult to predict.

Future Outlook

The company expects to continue to invest in sales and marketing and research and development to drive future growth. However, the July 19th incident is expected to continue to impact future results, including elongated sales cycles and increased contraction.

Industry Context

The cybersecurity market is intensely competitive and characterized by rapid changes in technology and customer requirements. CrowdStrike is a leader in cloud-based endpoint security, but faces competition from legacy antivirus providers, alternative endpoint security providers, network security vendors, and cloud security vendors. The company's focus on AI-native solutions positions it well for the future, but it must continue to innovate and adapt to evolving threats.

Comparison to Industry Standards

  • CrowdStrike's subscription revenue growth of 31% is strong compared to the overall cybersecurity market, which is growing at a slower pace.
  • The company's ARR of $4.0 billion is a significant achievement, placing it among the leaders in the endpoint security space.
  • The dollar-based net retention rate of 115% indicates strong customer loyalty and expansion, which is a key metric for SaaS companies.
  • However, the net loss of $16.8 million in Q3 is a concern, as many of CrowdStrike's competitors are profitable or have higher profitability.
  • Companies like Palo Alto Networks and Fortinet, while having different product mixes, are often compared to CrowdStrike in terms of cybersecurity market leadership and financial performance. CrowdStrike's growth rate is higher, but its profitability is lower.
  • The impact of the July 19th incident is a unique challenge for CrowdStrike, and its ability to recover from this will be a key factor in its future performance. Other cybersecurity companies have faced similar incidents, and their recovery trajectories can provide a benchmark for CrowdStrike.

Corporate Governance

Change TypeDescriptionEffective DateImpact Assessment
Bylaw AmendmentThe board of directors adopted and approved, effective immediately, amended and restated bylaws of the Company. The amendments set forth in the Amended and Restated Bylaws, among other things, enhance and clarify certain procedural and disclosure requirements related to shareholder nominations of directors and submissions of proposals regarding other business at annual or special meetings of shareholders, including with respect to (x) the information about any such shareholders and Stockholder Associated Persons (as defined in the Amended and Restated Bylaws) required to be disclosed to the Company and (y) certain other updates in light of the universal proxy rules adopted by the SEC pursuant to Rule 14a-19 of the Exchange Act. The Amended and Restated Bylaws also include updates to matters related to officer appointments and removals, and certain other technical, clarifying and conforming changes.2024-11-26The changes to the bylaws are primarily procedural and are not expected to have a significant impact on the company's operations or financial results.

Legal Proceedings

  • The company is subject to a number of legal proceedings in connection with the July 19 Incident, including a putative class action lawsuit alleging violations of federal securities laws, a putative class action lawsuit alleging negligence and violations of the California Unfair Competition Law, a putative class action lawsuit alleging negligence in the design and testing of the Falcon sensor and tortious interference, three derivative lawsuits alleging breach of fiduciary duty and violations of federal securities laws, and a complaint filed by Delta Airlines alleging computer trespass, breach of contract, and other claims.
  • The company is also involved in various other legal proceedings and subject to claims that arise in the ordinary course of business.

Stakeholder Impact

  • Shareholders are impacted by the net loss and the potential for continued negative impacts from the July 19th incident.
  • Employees may be affected by the company's efforts to manage costs and improve profitability.
  • Customers may be impacted by the July 19th incident and the company's efforts to remediate the issues.
  • Suppliers may be affected by the company's financial performance and its ability to meet its obligations.
  • Creditors may be impacted by the company's debt levels and its ability to service its debt.

Next Steps

  • The company will continue to invest in sales and marketing and research and development.
  • The company will focus on remediating the impact of the July 19th incident.
  • The company will integrate the acquisition of Flow Security.

Key Dates

DateDescription
2011-11-07CrowdStrike Holdings, Inc. was formed.
2019-04The Company entered into a Credit Agreement with Silicon Valley Bank and other lenders.
2019-05The board of directors adopted the 2019 Equity Incentive Plan and the 2019 Employee Stock Purchase Plan.
2021-01-04The Company amended and restated its existing credit agreement.
2021-01-20The Company issued $750.0 million in aggregate principal amount of 3.00% Senior Notes.
2022-01-06The Company modified the A&R Credit Agreement.
2023-09-28The Company acquired 100% of the equity interest of Bionic Stork, Ltd.
2024-03-26The Company acquired 100% of the equity interest of Flow Security Ltd.
2024-07-19The Company released a content configuration update for its Falcon sensor that resulted in system crashes for certain Windows systems.
2024-10-31End of the reporting period for the third quarter of fiscal year 2025.
2024-11-05The Company entered into an agreement to acquire all of the ownership interests in A.S. Adaptive Shield Ltd.
2024-11-15Number of shares of Class A and Class B common stock outstanding.
2024-11-20The acquisition of Adaptive Shield closed.
2024-11-26The Company's board of directors adopted and approved, effective immediately, amended and restated bylaws of the Company.

Keywords

cybersecurity, cloud security, endpoint security, SaaS, XDR, ARR, net retention rate, data security, incident response, AI

Disclaimer:The information provided here is for general informational purposes only and does not constitute financial advice, recommendation, or endorsement of any kind. It may contain errors or omissions. You should not rely on this information to make financial decisions. Always seek the advice of a qualified financial professional before making any investment or financial decisions. Use of this information is at your own risk.